(first-connection)= # First connection On power-up the device boots automatically (Buildroot Embedded Linux). The built-in CLI is `sysrepo-cli`, a local sysrepo client with tab completion. The simplest way to watch startup and perform the first configuration is the console. (local-console)= ## Local console (micro-USB) 1. Connect a micro-USB cable to the front-panel PWR/console port. 2. Open a serial terminal at **115200 baud, 8 data bits, no parity, 1 stop bit (115200 8N1)**. On Linux this is typically `/dev/ttyUSB0`; on Windows a COM port, for example with PuTTY. 3. Log in as **root**. No password is required on the local console. > **Security:** local root access without a password is intended for first setup. > Set a root password ({ref}`first-login-security`) and restrict physical access. (remote-login)= ## Remote login (SSH) Default remote access settings: | Item | Default | | -- | -- | | IP address | DHCP | | User | `dwdm` | | Password | `dwdm` | 1. Connect an Ethernet cable to **eth0**. The SFP port and eth1 also work, because all three ports share one bridge and one IP address (see {ref}`management-ports`). 2. Find the assigned address: on the console run `ifconfig`. The address is on the bridge interface **br0**, not on the physical ports. Alternatively, look it up in your DHCP server's lease list. 3. Check that the device is reachable: `ping IP_ADDRESS`. 4. Log in: ``` $ ssh dwdm@IP_ADDRESS (dwdm@IP_ADDRESS) Password: Connected via NETCONF [datastore target: operational] /> ``` The embedded CLI (`sysrepo-cli`) starts automatically. (first-login-security)= ## First login and security **Change the default credentials immediately.** - **dwdm password:** _TODO: command_ - **root password:** log in on the console as root, start `sysrepo-cli` and run: ``` > prepare /czechlight-system:authentication/users[name='root']/change-password (prepare: /czechlight-system:authentication/users[name='root']/change-password) > set password-cleartext "NEWPASSWORD" (prepare: /czechlight-system:authentication/users[name='root']/change-password) > exec RPC/action output: result = success ``` - **SSH public key (recommended):** generate a key on your PC: ``` ssh-keygen -t ed25519 ``` Then add it on the device (console, as root): 1. Start `sysrepo-cli`. 2. Enter: `prepare czechlight-system:authentication/users[name='root']/add-authorized-key` 3. Enter: `set key '...'`, replacing `...` with the public key in `~/.ssh/authorized_keys` format, for example `ssh-ed25519 AAAA... login@hostname.example.org`. 4. Enter: `exec` The key is active immediately; no reboot is needed.